Here is the surprise: the NIST 800-171 password requirements do not set a minimum password length, and they never say how often a password has to change. NIST Special Publication 800-171 Revision 2, the version your DFARS 252.204-7012 contracts point at, has four password requirements, 3.5.7 through 3.5.10, and every number in them is yours to define. You define a value, write it down, and prove your systems enforce it.

That is good news and a trap at once. Good news because the settings already in Microsoft 365 or Google Workspace satisfy most of it. A trap because an assessor does not judge whether your passwords are strong; they check that your written value matches your configured value.

The short version. Rev 2 asks for a defined complexity and change-of-characters rule the system enforces (3.5.7), a reuse ban for a number of generations you pick (3.5.8), temporary passwords changed at first logon (3.5.9), and passwords never stored or sent in the clear (3.5.10). Under the DoD Assessment Methodology, the first three are worth 1 point each and 3.5.10 is worth 5.

What the NIST 800-171 password requirements say, word for word

Requirement text is from NIST SP 800-171 Rev 2. Objectives are from NIST SP 800-171A (June 2018). Point values are from Annex A of the DoD Assessment Methodology, version 1.2.1, and match 32 CFR 170.24.

RequirementRev 2 text800-171A objectivesPoints
3.5.7Enforce a minimum password complexity and change of characters when new passwords are created.[a] complexity requirements are defined; [b] change of character requirements are defined; [c] the defined complexity is enforced when new passwords are created; [d] the defined change of characters is enforced1
3.5.8Prohibit password reuse for a specified number of generations.[a] the number of generations is specified; [b] reuse is prohibited during that number of generations1
3.5.9Allow temporary password use for system logons with an immediate change to a permanent password.One objective: an immediate change to a permanent password is required when a temporary password is used for system logon1
3.5.10Store and transmit only cryptographically-protected passwords.[a] passwords are cryptographically protected in storage; [b] passwords are cryptographically protected in transit5

Notice the pattern. Half the objectives say defined or specified, half say enforced. The first half is a paragraph in your password policy; the second is a screenshot of the matching directory setting. Miss either and, under 32 CFR 170.24, the whole point value is lost. Our post on what implemented actually means explains the mechanics.

3.5.7: complexity and change of characters

The Rev 2 discussion says this covers passwords used alone and as one factor of multifactor authentication, and that the number of changed characters refers to the number of changes required with respect to the total number of positions in the current password. No minimum length, no required mix of character types. Objective [a] is satisfied by whatever complexity rule you write down, provided [c] shows the system enforcing it.

The change-of-characters half worries people because no mainstream directory counts changed characters. The workable definition: a new password may not equal the current one or be a weak or banned variant. Microsoft Entra ID rejects the current password on every change and screens new ones against its banned password lists. Google Workspace's Enforce strong password option rates strength using breach data. Write that definition down and point to the setting.

3.5.8: reuse for a number of generations you specify

You pick the number, and the Rev 2 discussion adds that password lifetime restrictions do not apply to temporary passwords. The constraint is your directory. Entra ID blocks the last password on a change, and that depth cannot be raised for cloud-only accounts. Google Workspace lets you disallow reuse but not set how far back it looks. On-premises Active Directory has Enforce password history, 0 through 24. Define the generations your directory actually enforces; a policy promising 24 on a tenant that enforces one fails objective [b].

3.5.9: temporary passwords

Every admin-issued password is temporary: the new hire, the reset after a lockout, the account on the new CAM workstation. The one objective is that the system forces a change to a permanent password at first logon. Google Workspace's reset dialog has an Ask the user to change their password option, and an automatically generated password is reset at the next sign-in. In Microsoft 365 the flow is Users, Active users, Reset password. Evidence is the written procedure plus a screenshot of the option in use.

3.5.10: storage and transit, the five-point one

The Rev 2 discussion is one sentence: cryptographically-protected passwords use salted one-way cryptographic hashes of passwords. Cloud directories handle their own storage, so this objective is about everything else: the password spreadsheet on the shared drive, credentials pasted into a ticket or a chat, the shop-floor application that sends a logon over plain HTTP. Each is a plaintext password in storage or transit, and one is enough to lose 5 points. A password manager fixes storage. TLS on every logon page fixes transit.

The neighbors that decide whether the password matters

Where NIST 800-63B fits, and what Rev 3 changes

Where do defensible numbers come from? NIST itself. NIST SP 800-63B (June 2017, updated March 2020), section 5.1.1.2, requires user-chosen passwords of at least 8 characters, says verifiers should not impose composition rules and should not require periodic changes, while they must force a change on evidence of compromise. It also requires screening against a list of commonly used or compromised passwords and storing them salted and hashed. Its successor, NIST SP 800-63B-4 (July 2025), went further: 15 characters minimum when a password is the only factor, 8 when it is part of multifactor authentication, and the composition and periodic-change rules moved from should not to shall not.

800-63B is guidance for federal identity systems; 800-171 Rev 2 is the contract requirement. Nothing in Rev 2 requires 800-63B and nothing forbids it, so you can adopt its values as yours and cite NIST when an assessor asks why. NIST SP 800-171 Rev 3 (May 2024) closes the gap: it withdraws 3.5.8 and 3.5.9 and folds 3.5.10 into a new 03.05.07 Password Management requirement built around a compromised-password list, cryptographic protection in storage and transit, and organization-defined composition rules. Its discussion says long passwords or passphrases are preferable and that enforced composition rules provide marginal security benefits while decreasing usability. Rev 3 is not in your contracts yet; Rev 2 governs, as our Rev 2 versus Rev 3 post explains.

A password policy a small shop can adopt and evidence

Every value below is a NIST number or the value your directory enforces. Never write a stricter number than your directory can enforce; the mismatch is what fails the objective.

Defined valueWhere it is enforcedEvidence
Minimum length: 8 characters where every account has multifactor authentication, 15 where a password stands alone (the 800-63B-4 floors)Entra ID: fixed at 8. Google Workspace: 8 to 100. Active Directory: Minimum password length in Group PolicyDated screenshot; policy paragraph
Complexity and change of characters: the directory's rule, a banned or breached-password screen, no reuse of the current passwordEntra ID: three of four character types plus the banned list. Google: Enforce strong passwordSame screenshot; written definition
Reuse: the generations the directory enforces (1 on cloud-only Entra ID, up to 24 in Active Directory)Entra ID change history; Google Allow password reuse unchecked; AD Enforce password historyScreenshot; the number in the policy
Temporary passwords: change required at first sign-in, no exceptionsReset dialog option in either consoleOnboarding and reset procedure
Rotation: none on a schedule; forced when compromise is suspectedMicrosoft 365: Set passwords to never expire (recommended) is the default. Google: expiration offScreenshot; incident procedure
Storage and transit: password manager for shared credentials, no passwords in files, mail or chat, TLS on every logonPassword manager rollout; application inventorySeat count; note in the system security plan

How to check each objective without reading anyone's mail

Everything an assessor needs here is configuration, not content. In Microsoft 365: Entra ID, Authentication methods, Password protection for lockout and the banned list; Settings, Org settings, Security and privacy, Password expiration policy for rotation; Users, Active users, Reset password for temporary passwords. In Google Workspace: Security, Authentication, Password management, plus the reset dialog under Users. Screenshot each page with the date visible and staple it to the matching policy paragraph.

CMMC Map, CMMC compliance software for small defense contractors, works the same way. The Microsoft 365 and Google Workspace connectors read those configuration settings and nothing else, never mail or documents, and the assessment records which objective each screenshot answers. The assessment and the live SPRS score are free forever; the generated system security plan, plan of action, policies and readiness report are the one paid plan at $149 a month. Price a missing 3.5.10 on the free SPRS calculator.

What to do this week

  1. Screenshot the password settings page in your directory. That image is the enforcement evidence for 3.5.7[c], 3.5.7[d] and 3.5.8[b].
  2. Write the values you just saw into your password policy. Length, complexity rule, reuse generations, temporary-password rule, no scheduled rotation. That paragraph is 3.5.7[a], 3.5.7[b] and 3.5.8[a].
  3. Hunt for plaintext. Search the shared drive for files named passwords, logins or credentials. Every hit is a 5-point 3.5.10 finding until it moves into a password manager.
  4. Turn off scheduled expiration if it is still on. Both 800-63B editions say not to rotate without evidence of compromise, and Microsoft's admin center marks never expire as recommended.
  5. Reset one test account and watch. If the user is not forced to change the password at first sign-in, 3.5.9 is not met. Fix the checkbox, then write the procedure.

This is explanatory content about contractual requirements, not legal advice. Your contract clauses and your prime's flowdown letter govern.

See how your identification and authentication requirements score

The CMMC Map assessment walks all 110 requirements, the 11 in Identification and Authentication included, and gives you a live SPRS score, free, with no credit card.

Start free in CMMC Map
Free to assess · Documents $149/mo · No credit card